cairntir

v1.12.2 release acceptance

Status: COMPLETE — published and verified on 2026-09-08.

Verification correction, 2026-09-10: the installed-package assertion used for the semantic-recall claims below could pass on a zero-hit response that echoed the query. Those claims are withdrawn as unproved by that assertion. The publication, installed-byte comparisons and all-table restoration checks are separate evidence. The subsequent council audit records this gap and other reproduced integration failures in 1.12.2; a green release suite was insufficient.

Scope

This patch publishes the fixes from PR #108: bounded backup coordinator retries, successful completed snapshots despite delayed callbacks, workflow rollback and typed errors, valid float32 vectors, preserved access history, and verbatim transcript recovery. The changelog lists the individual changes. Schema 7, all 21 MCP tools and runtime dependencies remain unchanged.

The user explicitly requested 1.12.2 after checking PyPI publication status. Publication includes a new immutable tag, trusted publishing and fresh isolated installation checks. Production installation and app restarts are outside this release request; installed 1.12.1 and its backup policy remain in place.

Acceptance and evidence

The verification receipt records five actual historical broken/fixed comparisons, nine caught mutations with passing controls, and restored memories, vectors, provenance and task history. The accepted PR CI run passed all nine platform/Python combinations. Local selections passed all 1,672 tests at 92.25% combined statement-and-branch coverage (93.54% statements and 87.97% branches). The enforced gate is 92% combined, not 92% branches separately.

The release candidate must preserve that runtime source exactly except for the version constant, retain the 24 freeze manifests and 115 frozen artifacts, and keep dependency requirements unchanged. Existing installed-package verification runs through real CLI and MCP processes in disposable environments; it kills its own first host, resumes through another, restores every SQLite table and checks semantic retrieval. The public wheel must pass the same verifier and match the workflow and GitHub distributions, including signed source provenance.

New verification additions are solo-authored under the no-subagent constraint; no independent review is claimed. Targeted mutations are not exhaustive. Disposable destination failures and process interruption do not simulate a machine power cut. Exact interleavings behind two earlier CI failures were not logged; deterministic regressions prove the repaired defects without claiming those historical interleavings.

Release gates

At most two release repair rounds are available; at least 25% of work is reserved for verification. Publication gets one protected attempt. A partial publication retains its immutable tag and evidence; no version is reused. No new product behavior or weakened acceptance belongs in release preparation. Final disposition is COMPLETE, BLOCKED or EXHAUSTED, with actual evidence.

Local candidate

All 63 source/resource files match merged PR #108 except the version constant. Tests, verification scripts and workflows are unchanged. Version declarations agree at 1.12.2, and requirements and frozen acceptance remain unchanged. Thirty release/API/contract tests passed; lint, format, strict types, exception, release-tag, dependency, seam, commitment and documentation checks passed. The initial strict documentation build caught two links outside the docs tree; the corrected GitHub links pass without changing runtime code or tests.

The built sdist and wheel contain identical package payloads under the declared resource mappings. The installed wheel passed all 74 file comparisons, all 21 tool schemas, real CLI/MCP interruption and exact task resumption, all-table restoration and restored semantic recall. Candidate wheel SHA-256: 6a7fabef8fcca9444007f54f6ac396cf58a648b031f4f2bf549236d85fceb096. The public Linux-built distribution hashes are recorded below; archive metadata can differ from the Windows candidate.

Publication

Release PR #109 passed its full CI and CodeQL checks. Reviewed head 9ad5422cfca4cf13b3d4e550bfe76c739e720f54 and protected merge b3798b95a058f440448e3ae08d85a8be4123bb9b have identical trees. All nine native platform/Python jobs passed the strict 92% combined gate. Both behavioral jobs passed five broken/fixed historical comparisons and nine mutation/control pairs. Model evaluation and installed-package jobs passed.

The annotated immutable v1.12.2 tag identifies that merge. All five jobs in the trusted Release workflow passed on attempt 1. Version 1.12.2 is available on PyPI and GitHub.

Distribution SHA-256
cairntir-1.12.2-py3-none-any.whl 6b79adc1b92db524ad49765cdb1275ef9530b25c37bde6f67e161ba923f35d39
cairntir-1.12.2.tar.gz cab80aa9b0de69a7076c6c95b70a8951ede5c2c44cce5e78b7e0c89db6b02496

The tagged suite passed 1,670 tests at 92.118006% combined coverage. Linux skipped the Windows encoding regression; the self-referential publication check was deferred until PyPI upload and then passed in the publication verification job.

Both public distributions match the workflow and GitHub Release bytes. Signed provenance was verified against the exact repository, source commit, tag, release workflow, hosted runner and run attempt. The sanitized publication receipt records the artifact identities, gates and explicit limits.

The first fresh install could not resolve 1.12.2 immediately after upload. After the public simple index advertised both artifacts, a new environment installed cairntir==1.12.2 from that public PyPI index with locked runtime requirements. Dependency checks, redirected Windows help, version and bundled recipes passed. All 74 installed package files match the verified public wheel. Real MCP processes reported 1.12.2 and all 21 schemas; interruption and cross-host resumption retained the exact request and task revision. Restored memories, physical vectors, provenance and task history matched every table, and semantic retrieval worked from the restored store.

The production installation remains 1.12.1. Backup configuration and running applications were left in place. Production-store writes were limited to intentional release memories; no schema migration or reindex was required. Existing user-session reload was not claimed.